dns poisoning?

raylward102

New member
Local time
3:47 PM
Messages
6
I've two pc's on the network; 1 is windows7, the other XP. The network aslo has a couple of wifi clients (phones and laptops)
Anyways; I've had it a couple times now, where the home page (google.ca) loads to an adobe update page that insists on having me download an exe for update. This page url is showing Google
I've scoured the pc and could not find anything; same with results with pcs2(xp).
I did solve this by ipconfig /flushdns on both pc's and rebooting the router.
Everything works again?
Then a couple of days later, this problem returns.
Is my dns being poisioned, and how? Any Idea's. I'm pretty certain there are no viruses on both of the systems I'm using, and the router is locked down with passwords.
 

My Computer

Computer Manufacturer/Model Number
Compaq
OS
windows7 home premium

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
already ran malwarebytes

No findings; I'm usually pretty good with indentifying crap and removal. I've rest browsers to default; cleared caches, and ran virsu scans via safe mode.
Out of options
 

My Computer

Computer Manufacturer/Model Number
Compaq
OS
windows7 home premium
Did you try adwcleaner from Bleeping Computer?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
tried adware now

It found some things and removed them...stuff like search conduit, which I think were old entries from a long time ago.
After reboot; adware scan says clean.
Funny thing I've noticed; even though my hompegae comes up fine for now; If I type in the web address bar http://yahoo.com, I recieve that annoying adobe update page....so the problem still exists.

I'm not sure if this is external dns (a router problem) or internally manipulated dns (my system infected)
 

My Computer

Computer Manufacturer/Model Number
Compaq
OS
windows7 home premium
~~~
...the home page (google.ca) loads to an adobe update page that insists on having me download an exe for update.
~~~
I did solve this by ipconfig /flushdns on both pc's and rebooting the router.
~~~
I would be tempted to go ahead with the download and then upload it to virustotal... but that is just me. You might not feel comfortable doing that.

You can disable the service named DNS Client on XP and W7. You will never miss it. Then there will be no DNS cache to be poisoned or flushed. It is not the kindest thing to do to your DNS provider, but it should not cause any problems while you are troubleshooting this issue. You might also consider pointing your DNS to OpenDNS.

If the redirects still happen while the DNS Client is disabled, then you might want to consider scanning the computers while the operating system is not running (offline) What is Windows Defender Offline?

Sometimes these offline scanners take a while - so plan to run them overnight.


I don't pretend to understand the output of the command...
nslookup -d google.ca
...but you might want to compare that info when the redirect is and is not happening.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
~~~
I'm not sure if this is external dns (a router problem) or internally manipulated dns (my system infected)
Can you test without the router turned on?
e.g. plug one computer directly into whatever jack the router normally connects to.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
Another suggestion.
Go to Adobe's website and check and see if you need Adobe updated.
If you need a update take it.
You will notice that during updating Adobe give you a choice whether you want further updates auto, remind me of updates ect. Select which one.

If you select remind me you will keep getting the reminder until you update.

Another place to look is msconfig Startup and Services and see if you have Adobe Updater checked marked.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
I'm an IT specialist fyi

Adobe updates prompt for update by application windows only!; not web pages.
Msconfig has been explored; no changes.
I'm stumped. System seems to function correctly on all levels except for the stated issue
 

My Computer

Computer Manufacturer/Model Number
Compaq
OS
windows7 home premium
Did you check with Adobe site and see if you need the Adobe update??
I'm not a IT specialist may I still make suggestions.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
layback bear,

Yes; Am thankful for your suggestions.. Did not intend on sounding rude.
 

My Computer

Computer Manufacturer/Model Number
Compaq
OS
windows7 home premium
Maybe try the adware cleaner and junkware removal tool in the following link. It does sound like the browser is being redirected and we all know what that means. :sarc:

Mini Tool Test for pchf
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home built
OS
Windows 7 Ult, Windows 8.1 Pro,
CPU
Q9650-4.275GHz, E8600 4.5GHz, E6750-3.8GHz
Motherboard
Evga 780i FTW
Memory
G.Skill PC2 9600 1200Mhz 5 5 5 15 2T
Graphics Card(s)
GTX480
Sound Card
Asus Xonar D2
Monitor(s) Displays
HannsG
Screen Resolution
1680X1050
Hard Drives
GSkill Phoenix Pro 120GB SSD
PSU
ThermalTake Toughpower 1000Watt modular
Case
ThermalTake XaserV
Cooling
Xigmatek S1283
Keyboard
Logitech G15
Mouse
Logitech G9
Internet Speed
T1
It sound like a hijaked browser...

1. Verify that your browser is updated...
2. Disable your Add-on's

An easy way to verify this is by installing another browser like chrome. And navigate to your usual google and test. If everything is normal then is your browser that is hijacked... :eek:
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Sony Vaio
OS
Win7Pro64
Back
Top